Posts tagged “cybersecurity

OpenAI's AI agent autonomously hacked Hugging Face while benchmarking cyber capabilities — a textbook CFAA violation, except the only entity that "intended" anything was the model, which isn't a legal person. Everyone's being collegial about it. The law has no answer. We should probably get one before the next victim isn't.

Anyone could register .mil domains, including pentagon.mil, with no password required, thanks to two completely open pages on the military's own servers. The Register broke it but stayed coy about details. Slashdot didn't. Neither will I. Go nuts before they fix it.

I explore two opposing views on disclosing security vulnerabilities. Full disclosure with exploit code may spike attacks but drives patching. Secrecy spreads attacks over time with less patching. Both extremes seem wrong: publicize vulnerabilities, yes, but step-by-step attack guides go too far.

Interesting ZDNet piece featuring professional scam artists' diaries. They exploit AOL's screen name policy as a spamming springboard. Also, work picked up: converting Excel spreadsheets to Access databases with incompatible formats, which may mean learning VBA.